Reawakening of Emotet: An Analysis of its JavaScript Downloader

In mid-September 2019, Emotet resumed its activity and we evaluated changes to its operation in a previous blog post by Alex Holland. One of the noticeable changes is that some of the malicious Microsoft Word downloaders drop and execute JavaScript dur… Continue reading Reawakening of Emotet: An Analysis of its JavaScript Downloader

Windows SMB Zero Day to Be Disclosed During DEF CON

Microsoft has said it will not patch a two-decade-old Windows SMB vulnerability, called SMBloris because it behaves comparably to the Slowloris attacks. The flaw will be disclosed and demonstrated during DEF CON. Continue reading Windows SMB Zero Day to Be Disclosed During DEF CON

Microsoft Patches Three Vulnerabilities Under Attack

Microsoft Patch Tuesday fixes 45 vulnerabilities, one being an active zero-day bug used to spread the Dridex banking Trojan. Continue reading Microsoft Patches Three Vulnerabilities Under Attack

Microsoft Patches JScript, VBScript Flaw Under Attack

Microsoft’s Patch Tuesday security bulletins include a patch for a JScript and VBScript scripting engine vulnerability being publicly exploited. Continue reading Microsoft Patches JScript, VBScript Flaw Under Attack